Biometric JSON Web Tokens (BJWT): Enhancing Web API Security with Biometric Key Exchange and OTP-JWT Authentication
Mohamed Amer, Mohamed Amer, Tarek Salah Sobh · International Journal of Computer Applications · 2024
This paper presents an integrated framework called Biometric JSON Web Tokens (BJWT), combining the Enhanced Biometric Key Exchange Protocol (EBKEP) [1] with Time-Based One-Time Password (TOTP) for two-factor authentication, and a novel JWT-based token management system incorporating Auto Expire Auto Refresh (AEAR) features [2].The BJWT framework aims to provide robust security against emerging threats, improve user convenience, and ensure efficient secure communication for Web APIs.Through a detailed analysis of JSON Web Token (JWT) anatomy, including JSON Web Key (JWK), JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Algorithms (JWA), the proposed framework addresses vulnerabilities in traditional methods and offers a seamless, secure user experience.